Skip to content

nccgroup/ScoutSuite

Folders and files

NameName
Last commit message
Last commit date

Latest commit

May 10, 2024
7909f2f · May 10, 2024
Jun 28, 2023
May 10, 2024
Oct 16, 2023
Mar 5, 2024
Feb 4, 2024
Jul 22, 2020
Mar 16, 2020
Sep 16, 2021
Mar 16, 2020
Mar 16, 2020
Mar 16, 2020
Sep 22, 2022
Feb 4, 2024
Jul 28, 2020
Jul 28, 2020
May 8, 2024
Feb 7, 2020
Jun 14, 2023

Repository files navigation

Workflow CodeCov

PyPI version PyPI downloads Docker Hub Docker Pulls

Description

Scout Suite is an open source multi-cloud security-auditing tool, which enables security posture assessment of cloud environments. Using the APIs exposed by cloud providers, Scout Suite gathers configuration data for manual inspection and highlights risk areas. Rather than going through dozens of pages on the web consoles, Scout Suite presents a clear view of the attack surface automatically.

Scout Suite was designed by security consultants/auditors. It is meant to provide a point-in-time security-oriented view of the cloud account it was run in. Once the data has been gathered, all usage may be performed offline.

The project team can be contacted at scoutsuite@nccgroup.com.

Cloud Provider Support

The following cloud providers are currently supported:

  • Amazon Web Services
  • Microsoft Azure
  • Google Cloud Platform
  • Alibaba Cloud (alpha)
  • Oracle Cloud Infrastructure (alpha)
  • Kubernetes clusters on a cloud provider (alpha)
  • DigitalOcean Cloud (alpha)

Installation

Refer to the wiki.

Usage

Scout Suite is run through the CLI:

Running Scout Suite

Once this has completed, it will generate an HTML report including findings and Cloud account configuration:

Scout Suite Report

The above report was generated by running Scout Suite against https://github.com/nccgroup/sadcloud.

Additional information can be found in the wiki. There are also a number of handy tools for automation of common tasks.